SQL Injection Vulnerability in Blood Bank Management System by Code-Projects
CVE-2025-2044
Key Information:
- Vendor
- Code-projects
- Vendor
- CVE Published:
- 6 March 2025
Badges
Summary
A significant SQL injection vulnerability exists in the Blood Bank Management System version 1.0. This flaw arises from insufficient input validation in the /admin/delete_bloodGroup.php file, specifically in the way the application handles the blood_id parameter. An attacker could exploit this vulnerability remotely, enabling unauthorized access to the underlying database and potentially allowing them to manipulate or retrieve sensitive information. The public disclosure of this exploit heightens the urgency for users to implement security measures to protect their systems.
Affected Version(s)
Blood Bank Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved